---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Update Major Security Incident details

# Update Major Security Incident details {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

View and update specific details related to the major security incident such as Incident Record Details, Active Team participants, and the corresponding activity log.

All the related details of the major security incident are displayed with various Form sections on the Details tab of the workspace. Displays the details such as Incident Record Details, Active Team
participants, and the corresponding activity log. You can also view the linked SIR incidents, Vulnerability Group record details, and an ability to broadcast an activity posting to all the linked incident records.  
Primarily the Details tab contains:

1. Major Security Incident Form fields and incident-related UI sections.
2. Activity stream
{#msim-details-tab__ol_t2s_h2b_wrb}  
The following table provides the details of the major security incident form fields:{#msim-details-tab__table_hgw_4gb_wrb__entry__2}

| Field | Description |
|-|-|
| Incident ||
| Number | Major security incident record number. |
| Primary state | The primary state of the major security incident record. |
| Detection Date | The date when the major security incident was first created or proposed. Whenever you modify the Detection date on the Details tab, the date and time of the MSI is automatically calculated, refreshed, and displayed on the TimeTime since the incident started section on the Overview section of the workspace. |
| Title | Title of the Major security incident. |
| Code name | Code name for the major security incident. For example, Blue Tiger. |
| Next update on | The date and time of the next update for resolving the major security incident. For example, 5:00 pm EST on March 25, 2024. |
| Category | Category of the major security incident. |
| Sub category | Subcategory type of the major security incident. |
| Estimated resolution date | The estimated date by when the incident is expected to be resolved. The default value is 7 days from the time of the major security incident creation. |
| Priority | Priority of the major security incident. |
| Alert sensor | Alert sensor of the major security incident. For example, User Reported Phishing. |
| Source | Source of the major security incident. |
| Active Team ||
| Incident Manager | Name of the incident manager. |
| Assignment Groups | Indicates the different response teams and team members from each team who are actively working on the major security incident. |
| Candidate ||
| MSI candidate state | Indicates the major security incident candidate state such as proposed or promoted. If the incident is promoted, then the state is displayed as Accepted. |
| Promoted by | User who had promoted the major security incident. |
| Promoted | Date when the major security incident was promoted. |
| Justification | Justification of the major security incident. The justification should include the MSI number and the code name. |
| Potential impact | The potential impact and severity of the major security incident. The Potential impact should include the MSI number and the code name. |
| Restriction ||
| Enforce restriction | Select this option to enforce restrictions on certain major security incident restrictions. You can enforce restrictions to limit the view or modify access only to certain users or groups. For more information, see [Restrict access to certain major security incidents](https://servicenow-prod.fluidtopics.net/Ohvf4tDOTbfzQa0RMsVTsA "Manage access to sensitive major security incidents by restricting view and modify permissions to authorized users and groups."). |
| Allowed members | List of users who can access the major security incident. |
| Allowed groups | List of groups who can access the major security incident. |
| Other actions ||
| Attachment | Any attachments related to the major security incident. Select Select option to add attachments to the incident. |
| Conference Call | Use conference calls with the third-party service providers as a communication channel to meet with the stakeholders to resolve the major security incidents. For more information, see [Major Security Incident Management Conference Call Integration](https://servicenow-prod.fluidtopics.net/JdO_vR1dVAVy1RazuCR77w "With Major Security Incident Management conference calls integration, you can collaborate with your customers and peer agents to resolve customer issues using the video and screen sharing options in Microsoft Teams, Cisco Webex, or Zoom from the MSIM application.") |
[Table 1. Major Security Incident form sections]

{#msim-details-tab__table_hgw_4gb_wrb}

Activity:  
Use the Activity section to add your work notes and comments, and post your activity privately and also add additional comments as required using the Compose section. Save the activity after you post your work notes and comments to view the added activity or work notes in the Activity section.  
Note:  
Select the Show more details link to view the details of a specific security incident record, which are associated with that major security incident.  
Set your preferences to view the related activities such as:

1. Filters: Select the Filter sets icon to set filters.

   Set filters to view the activity conversations such as activities added on the work notes, email, Timeline, and any
   additional comments.
2. Flagged: Select the Flagged icon to flag the activities.

   Flag any important activity conversations for you to keep them handy.
{#msim-details-tab__ol_r4h_4kb_wrb}
* **[Restrict access to certain major security incidents](https://servicenow-prod.fluidtopics.net/Ohvf4tDOTbfzQa0RMsVTsA)**   
  Manage access to sensitive major security incidents by restricting view and modify permissions to authorized users and groups.

**Related concepts**   

* [Propose, promote, and link incident records](https://servicenow-prod.fluidtopics.net/sk9rqHFZOINPE0X~1U5vMg "Propose or promote security incidents as major security incidents when incidents are identified as critical threat to the organization.")
* [View Major Security Incident impact metrics](https://servicenow-prod.fluidtopics.net/3KBNBqRoz_BkHzUxpjZhkg "Provides up-to-date summary reporting of the impact and progress of major security incidents, which is an important aspect of managing a major security incident using the new workspace.")
* [View Major Security Incident trend charts](https://servicenow-prod.fluidtopics.net/i9L9Hku8t6K3KLufujwM_Q "View the major security incident impact progress metrics visualized as bar graphs and charts.")
* [Manage tasks in a Major Security Incident](https://servicenow-prod.fluidtopics.net/Yru0dCGME5pKnCMaKxhciw "The Task tab enables you to track and manage all the tasks associated with a major security incident from the MSIM workspace. You can view the various tasks using the default Visual Task Board (Kanban view) or the List view.")
* [Track collaboration activity via MSIM workspace](https://servicenow-prod.fluidtopics.net/oN75Hkl13nFA0yi30ej7pw#collab-tab "Track chat and file activities related to resolving major security incidents through the MSIM Workspace.")  
**Related tasks**   

* [Using MSI List view in the MSIM workspace](https://servicenow-prod.fluidtopics.net/KCnBshkJxFxNQC_44tHI8g "With the list view in the MSIM workspace, you can view proposed, promoted, and rejected major security incidents.")
* [Link additional records to Major Security Incident](https://servicenow-prod.fluidtopics.net/_LFdjo1aOyMiYBIDPKWA7Q "In the workspace, use the linking records functionality to link any related Security Incident records and its child security incidents, Remediation Tasks from Vulnerability Response, and Security Cases from Threat Intelligence to a Major Security Incident (MSI) record.")
* [Unlink records from Major Security Incident](https://servicenow-prod.fluidtopics.net/T0_CeewhEttOZPLLg8B4Ww "Using the Major Security Incident Management workspace, unlink the major security incident records from the Linked Records section.")
* [Create and distribute MSIM Status Reports](https://servicenow-prod.fluidtopics.net/~mxDy9mmDysMOt7PL5mv3A "As a Major Security Incident (MSI) manager, you can create and distribute the different status reports to different stakeholders at various intervals based on the configured report template or a previous status report throughout the course of the major security incident resolution.")

*[\>]: and then


